Abdolmadjid Masoomi
← All topics

privacy

70 pieces

  • AI Companion Chatbot Laws: What They Require for Minors

    Disclosure, crisis protocols and age-aware design are becoming the legal baseline.

    New ai companion chatbot laws mandate disclosure, crisis intervention, and minor protections. These statutes set a legal floor for safety but do not address the engagement mechanics that drive dependency. Builders and parents must look beyond compliance to understand true risk.

    2026-09-14 · technical-essay · 10 min read

  • AI Companions and Loneliness: Comfort That Never Pushes Back

    The risk of AI companionship is not that it feels real but that it is frictionless.

    Companion products optimised for engagement remove the necessary friction of human relationships. This creates a dynamic where emotional attachment to ai grows without the reciprocal demands that sustain real bonds. We must examine whether this frictionless comfort displaces the difficult but essential work of human connection.

    2026-09-14 · technical-essay · 8 min read

  • AI Meeting Note-Takers: Who Consented to the Recording?

    A bot invited by one participant records everyone, and the transcript lives on after the call.

    AI note taker consent is often assumed rather than obtained, creating legal and ethical risks. One participant’s invitation does not grant permission to record others. This analysis examines the collision between automated transcription and privacy norms.

    2026-09-14 · technical-essay · 7 min read

  • AI Sextortion: What Parents Should Do in the First Hour

    The image does not have to be real for the threat to work, which changes the conversation you need to have.

    Generative tools mean extortion no longer requires a child to have shared anything, so prevention talks built on 'never send photos' leave children feeling guilty for crimes committed with their public pictures. The first hour matters: do not pay, preserve evidence, report to the platform and child-protection hotlines, use hash-based takedown services, and tell the child explicitly that they are not in trouble.

    2026-09-14 · technical-essay · 8 min read

  • AI Toys and Smart Speakers in a Child's Room: What They Record

    A talking toy is a microphone that a child confides in; set it up as if every conversation will be kept.

    Conversational toys and smart speakers in a child's room are designed to encourage free speech, turning private spaces into sources of stored data. Understanding ai toys privacy requires examining how these devices capture, process, and retain voice recordings that children cannot meaningfully consent to.

    2026-09-14 · technical-essay · 8 min read

  • Broken Object Level Authorization: The API Flaw Behind Big Leaks

    Change one ID in a request and read someone else's records: the most common API failure.

    Broken object level authorization allows attackers to access data belonging to other users by simply altering identifiers in API requests. This vulnerability persists because many frameworks separate authentication from authorisation, leaving ownership checks to individual endpoints. Fixing it requires structural changes to how systems verify user permissions.

    2026-09-14 · technical-essay · 9 min read

  • Can Your Employer See Your Screen? Workplace Monitoring Explained

    What monitoring software can capture, what it usually does, and where personal devices stand.

    Employees often underestimate the visibility of managed work laptops while overestimating employer access to personal phones. The privacy risk lies in mixing these environments, as ownership and management dictate data exposure. Understanding these boundaries is essential when asking can my employer see what i do on my computer.

    2026-09-14 · technical-essay · 9 min read

  • Cloud Misconfiguration: Why Exposed Storage Keeps Happening

    Drift and convenience defeat one-time audits; guardrails have to sit above individual accounts.

    Cloud misconfiguration persists not from negligence but from the friction between rapid deployment and static controls. When infrastructure changes faster than policy, convenience wins. Sustainable security requires organisational guardrails that make incorrect states impossible, rather than relying on audits that miss the next change.

    2026-09-14 · technical-essay · 8 min read

  • Crossing a Border With Your Phone: How to Prepare Your Devices

    At a border the threat is compelled access, which calls for carrying less rather than encrypting more.

    A border phone search targets compelled access, not theft. Encryption alone fails when you must unlock the device. The effective defence is data minimisation: carry only what you need, keep the rest in accessible accounts, and power down before inspection.

    2026-09-14 · technical-essay · 7 min read

  • Cyber Incident Reporting Deadlines: Several Clocks, One Incident

    A single breach can trigger 24-hour, 72-hour and materiality-based deadlines to different regulators.

    Organisations often anchor on the GDPR 72-hour window and miss earlier triggers. Mapping the specific events that start each clock matters more than memorising durations. Clear cyber incident reporting requirements prevent regulatory penalties and reputational damage.

    2026-09-14 · technical-essay · 9 min read

  • Digital Legacy: Planning Your Accounts and Photos After Death

    Setting up legacy contacts and password inheritance ensures your family can access or close accounts without legal gridlock.

    Digital legacy planning prevents your family from being locked out of essential accounts and memories. Proactive configuration of legacy contacts and secure password sharing is the only reliable method to manage posthumous access. Without it, legal processes often fail to resolve technical barriers.

    2026-09-14 · technical-essay · 9 min read

  • Email Aliases and Burner Numbers: Everyday Privacy Tools

    Masked emails and temporary phone numbers reduce spam and tracking, but they do not hide your identity from determined adversaries.

    Email alias privacy is a practical defence against data brokers and automated spammers, yet these tools create significant management overhead and offer no protection against targeted surveillance. Burner numbers serve similar friction purposes in verification flows but vanish when providers demand persistent identity. Understanding their limits is essential for anyone building a resilient digital life.

    2026-09-14 · technical-essay · 10 min read

  • Griefbots: Talking to an AI Version of Someone Who Died

    A simulation built from a person's messages can comfort, short-term, but distort memory long-term.

    Griefbots offer a simulation of the deceased, optimised for comfort rather than truth. They risk replacing genuine memory with a compliant echo. Survivors must weigh the value of presence against the cost of accuracy.

    2026-09-14 · technical-essay · 8 min read

  • Health Data Outside HIPAA: What Your Apps Are Allowed to Share

    Most people assume medical privacy law follows health data; it mostly follows the doctor.

    HIPAA binds providers, insurers and their contractors, so the same heart-rate or cycle data is protected in a clinic record and largely unprotected in a consumer app. Understanding which laws actually apply to apps tells people what to ask before they log symptoms.

    2026-09-14 · technical-essay · 8 min read

  • Home Router Security: The Settings That Don't

    Hiding the network name changes nothing; the admin password, updates and remote management change almost everything.

    Most people waste time on rituals that feel secure while ignoring the controls that actually matter. Effective home router security settings focus on access control, patching, and isolation rather than cosmetic changes. This guide separates signal from noise to protect your network.

    2026-09-14 · technical-essay · 10 min read

  • How to Get a Deepfake Image Removed Under the Take It Down Act

    The 48-hour removal duty is a real lever, but it works best when the request is prepared like evidence.

    Victims of synthetic media abuse now have a statutory clock to demand removal. A take it down act removal request forces platforms to act quickly, but success depends on precise documentation and understanding the legal boundaries of the duty.

    2026-09-14 · technical-essay · 8 min read

  • How to Remove Your Personal Information From Data Brokers

    Removal is a recurring process, and the only regimes that work are the ones that repeat.

    You cannot permanently erase your digital shadow with a single request. To effectively remove personal information from data brokers, you must treat privacy as a maintenance schedule rather than a one-time event. This guide outlines the mechanisms of data aggregation and the practical steps to minimise your exposure.

    2026-09-14 · technical-essay · 8 min read

  • Juice Jacking: Is Public USB Charging Actually Dangerous?

    The famous warning is mostly theory; the smaller real risk is tapping Trust on a prompt.

    The concept of juice jacking is widely warned about but rarely documented in the wild. Treating it as a primary travel threat displaces attention from more common risks. The sensible approach is simple: use your own charger or a power-only adapter, and never accept a data prompt on an unknown device.

    2026-09-14 · technical-essay · 8 min read

  • Running a Local LLM for Privacy: What You Gain and What You Don't

    Local models remove the provider from the picture, not the risks of what the model is allowed to do.

    Running a local llm privacy is often misunderstood as a total security solution. While it stops data leaving your device, it does not protect against prompt injection or supply chain risks. Local deployment is a privacy choice, not a comprehensive security strategy.

    2026-09-14 · field-note · 8 min read

  • School Apps and Student Data: Questions Parents Can Ask

    Schools adopt dozens of platforms a year; parents can ask five questions that reveal the risk.

    Educational technology is often approved one tool at a time, leaving no one to track the combined data footprint of a child. Parents do not need legal expertise to engage; asking what is collected, who processes it, and how it is deleted surfaces most problems in student data privacy.

    2026-09-14 · technical-essay · 8 min read

  • Setting Up a Child's First Phone: Contact Controls Before Content

    The biggest risk on a first phone is who can reach the child, not what they might see.

    Most parents focus on content filters for their child's first phone safety settings, yet the fastest escalation of harm comes through contact. Configuring who can message, call, and add the child matters more than any filter list. Prioritising communication limits reduces exposure to grooming and scams before they begin.

    2026-09-14 · technical-essay · 8 min read

  • Should You Trust AI Medical Advice? How to Use It Safely

    Chatbots are good at explaining and preparing questions, and keeping decisions where accountability exists.

    People increasingly ask chatbots about symptoms, but the danger lies in triage decisions where confident errors cause harm. Using AI to understand results and prepare questions for a clinician captures benefit while keeping accountability clear.

    2026-09-14 · technical-essay · 10 min read

  • Smart Glasses and Facial Recognition: Privacy for the People in View

    Consent designs built around the wearer ignore everyone the camera looks at.

    Smart glasses privacy is compromised by a design that places consent solely with the wearer, leaving bystanders with no agency. When recording merges with identification, ambient capture becomes targeted surveillance, demanding regulatory focus on capability rather than etiquette.

    2026-09-14 · technical-essay · 10 min read

  • Using ChatGPT as a Therapist: Where It Helps and Where It Harms

    Structured exercises and rehearsal can help; crisis, delusion and dependency are where it fails.

    General chatbots can be genuinely useful for structured, low-stakes work such as practising a difficult conversation or working through a worksheet. They fail predictably in crisis, in affirming distorted beliefs and in creating dependence, so safe use means clear boundaries on purpose, a human in the loop for anything serious, and awareness that the chat is not confidential.

    2026-09-14 · technical-essay · 7 min read

  • What Your Stolen Identity Sells For, and Why It Is So Cheap

    Low prices for stolen records reflect oversupply, not low harm.

    The question of how much is stolen data worth often leads to a false sense of security. Low market prices mask the severe risk of identity reconstruction. Understanding the mechanics of value reveals why individual records are cheap but dangerous.

    2026-09-14 · technical-essay · 8 min read

  • Your AI Chat History Is a Record: Courts, Breaches and Reviewers

    The bigger privacy risk is not training; it is logs that can be produced, reviewed or leaked.

    Most people assume the greatest risk of using AI is model training, but the real danger lies in retained chat logs. These records behave like email: they are discoverable in litigation, subject to preservation orders, and exposed in breaches. Understanding whether are ai chats private requires looking beyond training data to how organisations store and process your inputs.

    2026-09-14 · technical-essay · 8 min read

  • Insecure Plugin Integrations

    The assistant became the place where two estates meet, and nobody negotiated the terms

    Connecting an assistant to an external tool extends your trust boundary to an operator you have no agreement with, at a seam authenticated more weakly than anything else you run. What the integration can actually see, and the line where the problem stops being technical.

    2026-09-13 · technical-essay · 3 min read

  • 'Military-Grade Encryption' Means Nothing

    A guide to the security vocabulary that sounds strongest and tells you least

    Some security claims describe a property that can be checked. Others describe a feeling. Sorting the phrases in common marketing use into those that carry information and those that carry only reassurance, with the question that exposes each one.

    2026-09-12 · technical-essay · 3 min read

  • Age Verification and the Identity Trap

    Proving you are over eighteen usually means proving exactly who you are, and the two are not the same requirement

    A system that checks age by collecting identity documents has answered a yes-or-no question by building a register. The gap between what is being asked and what is being collected, why implementations default to the wider one, and what a narrow answer would look like.

    2026-09-12 · technical-essay · 3 min read

  • Anonymised Is a Verb, Not a State

    Removing names is the easy part, and it is almost never the part that identifies you

    Organisations describe data as anonymised after removing direct identifiers, then release or trade it as though identification were now impossible. What actually identifies a person in a dataset, why re-identification succeeds so reliably, and what the word would have to mean to be worth anything.

    2026-09-12 · technical-essay · 3 min read

  • Deleting Your Account Rarely Deletes You

    What the delete button reaches, what it cannot reach, and why the difference is structural

    Account deletion removes your access and usually your profile. It does not reach backups, derived data, systems that already copied the record, or the conclusions drawn from it. What actually happens after the confirmation dialogue, and the one case where deletion genuinely works.

    2026-09-12 · technical-essay · 3 min read

  • Encrypted at Rest Is the Weakest Claim on the Page

    It defends against one specific event, it is nearly universal, and it is presented as though it were the headline

    Almost every service states that data is encrypted at rest. The claim is usually true and protects against a narrow scenario: somebody obtaining the physical medium. Against the threats people are actually worried about, it does approximately nothing, and understanding why clarifies what to look for instead.

    2026-09-12 · technical-essay · 3 min read

  • How to Read a Breach Notification

    The letter is a carefully constructed document, and the interesting information is in what it declines to say

    Breach notifications follow a recognisable template built under legal advice and time pressure. Reading one properly means attending to the tense of the verbs, the scope of the nouns, and the questions the letter answers instead of the ones you asked. A guide to the standard phrases and what each one leaves open.

    2026-09-12 · technical-essay · 4 min read

  • How to Read an Interface

    A method for working out what a product optimises, using nothing but a stopwatch and a count of taps

    You can infer what an organisation measures from the layout it ships, without access to anybody's intentions or documents. Five signals to look at, why asymmetry of effort is the reliable one, and how to state the reading as evidence rather than as an accusation.

    2026-09-12 · technical-essay · 4 min read

  • Indirect Prompt Injection in Enterprise Knowledge Bases

    The payload arrives through a sanctioned route, sits inert, and fires on somebody else's question

    The attack surface is the document store. A payload enters through a supplier's file or a wiki edit, waits in the index, and is pulled into context by an unrelated query. Why scanning at upload does not catch it, and what treating retrieval as provenanced data actually buys.

    2026-09-12 · technical-essay · 4 min read

  • Metadata Is the Message

    Why who you contacted, when, and from where says more than what you said

    Content is expensive to analyse and easy to encrypt. Metadata is cheap to analyse, hard to hide, and sufficient for most conclusions anybody wants to draw about a person. Why the distinction is drawn where it is, and what follows from it.

    2026-09-12 · technical-essay · 4 min read

  • Passkeys Without the Marketing

    What replaces the password, and the part nobody mentions until you change phones

    Passkeys replace a shared secret with a key pair, which removes an entire category of attack at a stroke. They also move the hard problem from remembering to recovery, and the recovery story is where the differences between implementations actually live.

    2026-09-12 · technical-essay · 4 min read

  • Privacy Is Not Secrecy

    The strongest argument against privacy only works if you accept a definition nobody actually uses

    Nothing to hide is the most durable objection in this field, and it survives because it quietly redefines privacy as concealment of wrongdoing. What privacy actually is — contextual control over who knows what about you — and why every person making the argument already practises it.

    2026-09-12 · technical-essay · 3 min read

  • Public Wi-Fi: What Actually Changed

    The advice everyone repeats was written for an internet that no longer exists

    Warnings about coffee shop networks date from a period when most traffic was unencrypted. Nearly all of it is encrypted now, which changes what a hostile network can and cannot do. What the real remaining risks are, and which of the familiar precautions still earn their place.

    2026-09-12 · technical-essay · 3 min read

  • RAG Vector Database Exploitation

    The index is filed as infrastructure and behaves as memory, so write access to it is write access to what the system believes

    A vector store is usually secured like a database and used like a recollection. Why permissions applied at the document store do not travel into the index, why the embedding often outlives the file it came from, and what signing and re-embedding actually fix.

    2026-09-12 · technical-essay · 3 min read

  • The Backup You Have Not Tested Does Not Exist

    Backup is a verb about restoring, and almost everybody has only done the first half

    Most backup arrangements have never been used. The failure modes that emerge only on the day you need them, why the encryption question is sharper here than anywhere else, and a test that takes an hour and settles it.

    2026-09-12 · technical-essay · 4 min read

  • The Consent Popup Is Not Consent

    What the banner is actually for, why it is designed to be tiring, and what genuine consent would look like

    Cookie banners were meant to give people a choice and instead taught a generation to click whatever makes the overlay disappear. The mechanism by which a consent requirement became a consent ritual, and what would have to change for the word to mean anything.

    2026-09-12 · technical-essay · 3 min read

  • The Cost of Being Findable

    Publishing under your own name is a security decision before it is a career one

    Building a public record under a real name creates reach and creates exposure, and the two arrive together. What actually becomes searchable, which categories of harm follow, and how to publish deliberately rather than discovering the terms afterwards.

    2026-09-12 · founder-essay · 4 min read

  • The Default Is the Policy

    What a system does when nobody chooses is what it does, and everything else is documentation

    Settings pages describe what is possible. Defaults describe what happens. Since almost nobody changes a default, the default is the operative policy of a system regardless of what any document says — which makes choosing defaults the most consequential design decision most teams make without noticing.

    2026-09-12 · technical-essay · 3 min read

  • The Face Is the Password Now

    Biometrics solve the problem of remembering and create the problem of not being able to change

    A face unlocks a phone, clears a border and, increasingly, confirms an identity to a service that has never met you. What biometrics genuinely fix, the property that makes them different from every other credential, and where the distinction between matching on your device and matching on somebody else's server decides everything.

    2026-09-12 · technical-essay · 4 min read

  • The Hidden Infrastructure of Shadow AI

    An unapproved tool inherits the reach of the systems it sits upstream of

    Staff paste sensitive material into endpoints nobody approved. The exposure is not the pasting — it is that those endpoints sit upstream of pipelines the organisation does control, so an unsanctioned tool acquires reach it was never granted.

    2026-09-12 · technical-essay · 3 min read

  • The Password Advice That Made Things Worse

    Rules designed to increase entropy produced predictable behaviour instead, and the behaviour was foreseeable

    Complexity requirements, forced rotation and composition rules were adopted almost universally and made outcomes worse in measurable ways. Why each backfired, what humans reliably do when given a rule they cannot satisfy honestly, and what the current guidance says instead.

    2026-09-12 · technical-essay · 4 min read

  • The Permission You Granted Once

    Consent is asked at a single moment and exercised continuously, and nothing in any interface shows you the difference

    Application permissions are granted once, in a second, and then apply indefinitely to software that updates itself. The structural gap between a one-time decision and continuous execution, and the small number of practices that actually narrow it.

    2026-09-12 · technical-essay · 3 min read

  • The Record Outlives the Decision

    Every privacy question people argue about is really a question about how long something is kept and by whom

    Consent, targeting, surveillance, data brokerage and the ethics of machine learning are usually argued as separate disputes. They share one structure: a decision made in a moment produces a record that persists far beyond it, and nearly all the harm lives in that gap. A single frame for the field, and what follows from it.

    2026-09-12 · technical-essay · 5 min read

  • The System Cannot Be Asked Why

    Most disputes about automated decisions are really disputes about who has to explain themselves, and to whom

    Bias, transparency, consent and accountability are argued as separate problems in automated systems. They share a structure: a decision is produced that affects a person, and the capacity to demand an explanation has moved somewhere the person cannot reach. A single frame for the field, and what follows for anyone building these systems.

    2026-09-12 · technical-essay · 5 min read

  • Two-Factor Authentication, Ranked

    From the one that stops nearly everything to the one that is mostly a formality, with the reason for each position

    The common second factors are not equivalent, and the differences are not marginal. An ordering by what each actually resists, why the weakest is still worth enabling, and the failure that defeats most of them regardless of which you chose.

    2026-09-12 · technical-essay · 4 min read

  • What a Consent Record Actually Proves

    It is excellent evidence of process and almost worthless evidence of preference, and those get quoted interchangeably

    Systems store a timestamp, a document version and an identifier, and call the result consent. That record answers one question well and a different question not at all. Which is which, why only one of the standard conditions is testable in code, and what a builder can do about it this quarter.

    2026-09-12 · technical-essay · 4 min read

  • What a Security Audit Does Not Cover

    The scope is the whole content of the finding, and it is the part left off the badge

    An audit report says something precise about a defined system at a defined moment. The badge on the website says something vague about a company forever. How to read the difference, and the four questions that recover the real meaning from a claim of having been audited.

    2026-09-12 · technical-essay · 3 min read

  • What a VPN Does Not Do

    The three things it genuinely changes, and the many it is sold as changing

    A VPN moves the point at which your traffic joins the public internet. That is a real and sometimes valuable change. It is not anonymity, it is not encryption of things that were not already encrypted, and it does not remove you from the systems that identify you.

    2026-09-12 · technical-essay · 4 min read

  • What Happens When the Company Dies

    Acquisition, insolvency and discontinuation are data events, and almost nobody plans for them

    Assessments of a service ask whether it is secure and whether it is trustworthy. They rarely ask what becomes of the data if the company is sold, wound up, or simply stops. Those three endings have different mechanics and different consequences, and all three are ordinary.

    2026-09-12 · technical-essay · 4 min read

  • What I Look For When I Audit a Service

    A short list, in the order I check it, and why the first item is almost always the last word

    A practical procedure for assessing whether a service can do what it says about your data, written as an order of operations rather than a checklist. Most assessments are settled by the first two questions; the rest establish how much of the answer was deliberate.

    2026-09-12 · founder-essay · 4 min read

  • What Smart Devices Send Home

    A speaker that only listens for its wake word still has a great deal to say about you

    The argument about whether these devices record everything misses the more consequential point: the traffic they generate when working exactly as described already describes your household in detail. What leaves, what it reveals, and the questions that separate a device you can live with from one you cannot.

    2026-09-12 · technical-essay · 4 min read

  • What Your Browser Extension Can See

    The most privileged software on your machine is usually the software you thought about least

    An extension with permission to read and change data on all sites can see everything the browser sees: the pages, the forms, the session that keeps you logged in. Why that permission is so commonly granted, what it actually permits, and how the risk arrives long after installation.

    2026-09-12 · technical-essay · 3 min read

  • Who Are You Actually Defending Against

    Most personal security advice is given without asking the one question that determines whether any of it applies

    Advice is dispensed as though everyone faced the same adversary. The measures that protect against an opportunist are different from those that matter against somebody who knows you, and different again from an adversary with legal authority. A method for working out which set applies to you, and why copying somebody else's precautions usually wastes effort.

    2026-09-12 · technical-essay · 4 min read

  • Who Holds the Key

    One question organises almost everything in practical security, and most products answer it without being asked

    Transport encryption, storage encryption, password managers, backups, messaging, biometrics and cloud storage look like separate subjects. They are one question repeated: who is in a position to read this, and what would it take. A single frame for the whole field, and where each common arrangement sits inside it.

    2026-09-12 · technical-essay · 6 min read

  • Why I Publish What My Software Cannot Do

    Stated limitations are expensive, which is exactly why they are worth reading and worth writing

    Every product page lists capabilities. Almost none list the things the system is structurally unable to do. An argument for publishing limitations as a design discipline rather than a confession, and what changes in the engineering when you commit to it.

    2026-09-12 · founder-essay · 4 min read

  • Why Phishing Still Works

    It is not that people are careless. It is that the message arrives when the story already makes sense.

    Phishing is usually explained as a failure of user attention, which is why twenty years of telling people to be careful has not fixed it. A better explanation is that a convincing message arrives at a moment when it fits, and fitting is cheap to arrange.

    2026-09-12 · technical-essay · 3 min read

  • Your Car Is a Data Broker

    The vehicle collects more than the phone did, and almost none of the habits people have built apply to it

    A modern car knows where it goes, how it is driven, who is in it, what is said near the microphone and which phone is paired to it. It has a permanent connection, an opaque update channel, and no meaningful setting to turn any of it off. What that implies, and the few points where a driver still has leverage.

    2026-09-12 · technical-essay · 4 min read

  • Your Password Manager Is Not the Weak Link

    The objection is intuitive, common, and wrong for a reason worth understanding

    Putting every password in one place sounds like concentrating risk, and the intuition is not stupid. It is wrong because it compares the wrong two options: not a manager against perfect discipline, but a manager against what people actually do instead.

    2026-09-12 · technical-essay · 3 min read

  • Before You Post That Photograph

    What actually reduces the exposure, what only feels like it does, and why the difference matters more for children

    Practical measures for photographs you share online, ordered by how much they actually change, and honest about which are close to useless. A companion to a longer argument about what retained images are worth to the systems that keep them.

    2026-09-11 · field-note · 5 min read

  • Browser-Level Encryption: What the Padlock Does Not Cover

    The difference between a connection nobody can read and a file nobody can read

    TLS protects a file while it moves. It stops protecting it the moment it arrives. This is the distinction between transport encryption, encryption at rest, and end-to-end encryption performed in the browser — stated in terms of who holds the key at each stage, because that is the only question that separates them.

    2026-09-11 · technical-essay · 4 min read

  • Free Is a Price

    What a service costs when it does not charge, and how to work out what you are paying before you sign up

    Every service is paid for. When the user is not the payer, the revenue has to come from somewhere, and the shape of that somewhere determines what the product is motivated to do. A method for reading a business model off a service before you build anything on top of it.

    2026-09-11 · technical-essay · 4 min read

  • What a Breach Actually Leaks

    Why the answer to 'were passwords exposed?' matters less than people think, and what to look at instead

    Breach notifications are written to be survivable, which makes them poor instructions. This separates the categories of data a breach can expose by how long each stays dangerous, and gives the reader a way to decide what to do that does not depend on the wording of the notice.

    2026-09-11 · technical-essay · 4 min read

  • What the Model Remembers

    Where the text you paste into an assistant goes, who can read it, and which of the usual reassurances actually mean something

    Pasting a document into a chat assistant is not the same kind of act as searching for something. This separates what happens to that text — the request, the retention, the human review, the training set — and gives the questions that distinguish a service that cannot read your input from one that merely says it will not.

    2026-09-11 · technical-essay · 5 min read

  • You Are the Training Set

    What the free photograph pays for, and who is holding it in fifteen years

    A birthday photograph uploaded today is not consumed and discarded. It is retained, indexed, and used to teach systems that will still be running when the child in it is grown. This is an argument about what that permits, written as a scenario, because the mechanism is ordinary and the consequence is not yet.

    2026-09-11 · founder-essay · 6 min read